OSVDB ID: 3428

Title: Symantec Automatic LiveUpdate Local Privilege Escalation

Info

Disclosure

Jan 13, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Symantec LiveUpdate contains a flaw that allows a local user to obtain SYSTEM privileges. The issue occurs when an interactive LiveUpdate session is available and allows a non-privileged user to manipulate the GUI functionality to gain elevated privilege.

Classification

Location: Local Access Required
Attack Type: Attack Type Unknown
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Symantec Corporation

Windows LiveUpdate

1.70.x
1.90.x

References

Credit

  • KF - dotslashsnosoft.com - Secure Network Operations


Direct URL: http://osvdb.org/3428